
xnu
Hybrid kernel combining Mach, FreeBSD, and IOKit for macOS and iOS. Provides core OS services, driver framework, and security policy enforcement on…

Hybrid kernel combining Mach, FreeBSD, and IOKit for macOS and iOS. Provides core OS services, driver framework, and security policy enforcement on…

Custom C exploit for CVE-2020-8423 targeting MIPS routers, featuring hooked open() syscall and tailored for Linux kernel 2.6.31.

Linux libfprint driver for the Focal-systems FT9201 (2808:93a9) USB fingerprint reader — runs FocalTech's own Windows matching engine natively on…

Library for WCH CH56x-based boards with tested USB3/USB2/HSPI/SerDes drivers, logging and deferred interrupts

Proof-of-concept exploit for CVE-2023-20126 targeting Cisco SPA phone adapters. Uploads malicious firmware to gain a root shell on port 23000/tcp via…

CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)

SPI flash read MitM attack PoC

BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748

Open-source hardware security toolchain for power trace capture, side-channel analysis, and glitching/fault-injection attacks on embedded devices and…

CVE-2025-21479 proof-of-concept, I think

The results of my small term paper on the topic of the Internet of Vulnerable Things and the exploit for CVE-2022-48194.

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Proof-of-concept exploit for CVE-2024-36877 targeting firmware vulnerabilities, with detailed write-up and binary exploitation techniques.

An implementation of baton drop (CVE-2022-21894) for armv7 (MSM8960)

Official Intel microcode data files for updating processor firmware to mitigate security vulnerabilities and address functional issues on Linux…

Active fingerprinting tool that identifies 16 embedded TCP/IP stacks on network devices using ICMP, TCP, HTTP, SSH, and FTP probing techniques for…

BLE-based Fitbit research tool for authentication replay, encrypted activity dump decryption, memory/firmware extraction, and custom firmware…

Voltage fault-injection modchip for black-box security evaluation of Starlink terminals, bypassing bootloader signature verification to execute…